CVE-2012-5781

Amazon Elastic Load Balancing API Tools - Man-in-the-Middle Attack via Unverified X.509 Certificate

Title source: llm
STIX 2.1

Description

Amazon Elastic Load Balancing API Tools does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to overriding the default JDK X509TrustManager.

References (1)

Core 1
Core References

Scores

EPSS 0.0013
EPSS Percentile 32.8%

Details

CWE
CWE-20
Status published
Products (10)
amazon/elastic_load_balancing
amazon/elastic_load_balancing 1.0 (2 CPE variants)
amazon/elastic_load_balancing 1.0.3.4
amazon/elastic_load_balancing 1.0.9.3
amazon/elastic_load_balancing 1.0.10.0
amazon/elastic_load_balancing 1.0.11.1
amazon/elastic_load_balancing 1.0.12.0
amazon/elastic_load_balancing 1.0.14.3
amazon/elastic_load_balancing 1.0.15.1
amazon/elastic_load_balancing 1.0.17.0
Published Nov 04, 2012
Tracked Since Feb 18, 2026